MALICIOUS
84
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The PDF is identified as an image-only lure, typical of phishing attacks designed to trick users into clicking a link. The embedded link directly points to a payload, indicating an attempt to deliver malware. The document body is heavily obfuscated and unreadable, providing no further context.
Machine Learning
- Nyx PDF Classifier clean score 0.0033
Heuristics 4
-
PDF link points directly to executable/archive payload critical PDF_DIRECT_PAYLOAD_LINKPDF contains a clickable HTTP(S) URI whose path ends in an executable, script, shortcut, disk image, or archive extension. Documents can legitimately link to installers, so this is a high-risk delivery indicator rather than a standalone exploit fingerprint.
-
Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LUREPDF has 2 image(s), only 0 text block(s), carries a click-outward action, and is only 74 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://adclick.g.doubleclick.net//pcs/click?f1587wub8-24-TzRtAOnedriveBskd&&adurl=//selectwendormo9tres.com?utm_content=AAhqplxaJo&session_id=3VHLBRuVfwDKTPWgylgR&id=b2WBu&filter=FSBMsIgzmQ-pIvZl&lang=zh&locale=US
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000da52.bindf81849862a3ba199bae1dffeee44aa39273d6c2c1d19d8550396604c8ec5c73 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDA52 | 5980 bytes |
font_01_sfnt_off0000edb4.binfcb5a74c7a9810c20dda22eccb67f73b069160eced8adcd7ee2e67464c96075c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEDB4 | 2407 bytes |
font_02_sfnt_off0000f8b9.binb3a607e4bf030e1c90b076d5f41e8dd93acbc6d87ac92987b19c8f825a9af62a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF8B9 | 6001 bytes |
font_03_sfnt_off00010e79.bin566618c4f33bb8cbf2331433175e253fedf1f79597e417124e5be3c2564a85e0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10E79 | 7300 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.